veragent-mcp
by lixiaowww
README.md
# Veragent MCP Server
<!-- mcp-name: io.github.lixiaowww/veragent -->
The trust layer for MCP — as an MCP tool. Let Claude (or any MCP client/agent) check
whether an MCP tool is **safe before installing it**, look up the most trusted tools,
or score an entire MCP stack — all backed by the [Veragent](https://veragent.store)
trust registry.
> ⭐ **Star this repo** · `uvx veragent-mcp` — check any tool's trust before you install · **[Get your tool SGC Certified →](https://veragent.store)** · [How we audit (open methodology) →](https://github.com/lixiaowww/veragent-audit)
## Tools
| Tool | What it does |
|------|--------------|
| `check_tool_trust(name)` | Veragent trust score + audit state for a tool/server/agent. Use **before** installing. |
| `list_trusted_tools(query, limit)` | The most trusted MCP tools, optionally filtered. |
| `scan_mcp_stack(mcp_config)` | Score a whole `mcp_settings.json` — per-server risk + summary. |
## Install (Claude Desktop)
Add to your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"veragent": {
"command": "uvx",
"args": ["veragent-mcp"]
}
}
}
```
Then ask Claude: *"Is the playwright-mcp server safe? Check Veragent."*
## Run locally
```bash
uvx veragent-mcp
# or
pip install veragent-mcp && veragent-mcp
```
## Configuration
- `VERAGENT_API_BASE` — override the API base (default `https://veragent.store/api/v1`).
## Honesty
Veragent labels static-analysis results as **Heuristic** and reserves **SGC Certified**
for behavioral-sandbox passes. Scores are reported with this distinction.
TDQS
A3.9/5.0
Scored across 3 tools
Disambiguation5/5
Each tool has a distinct purpose: checking a single tool, listing trusted tools, and scanning a full stack. No overlap.
Naming Consistency5/5
All tool names follow the consistent verb_noun pattern with snake_case, making them predictable.
Tool Count5/5
Three tools is appropriate for a security verification server, covering individual check, listing, and stack scan without excess.
Completeness4/5
The tool surface covers the main verification operations, though a detailed audit or reporting tool could enhance completeness.
Maintenance
ActivityInactive
ResponsivenessNo issues